Blacklisted IPs

Status
Not open for further replies.

P Jim

Forum User
Joined
Aug 26, 2020
Messages
8
Reaction score
0
I just completed a migration from v11 to v15.5. I have received the below email multiple times since. How does one determine whether to leave such IPs on the blacklist or move them to a whitelist?

IP 45.148.121.31 has been blacklisted on PBX avalonchurch.fl.3cx.us.
Affected Module: SIP Server/Call Manager

The IP 45.148.121.31 has been blacklisted for 1800 seconds. (Expires at: 2020/09/10 05:37:10).
Reason: Too many failed authentications! This IP Address has made numerous attempts to authenticate with 3CX with invalid authentication details. Therefore a blacklist rule has been created denying this IP to continue sending requests.

To delete this rule, login to the 3CX Management console > Dashboard > IP Blacklist. Enter this IP Address 45.148.121.31 in the search field and delete the entry.

You can whitelist the IP or you can permanently block this IP or the whole subnet it belongs to.

Visit this url for more information on black/white listing https://www.3cx.com/docs/allow-deny-ip-addresses/
 
Simple..

IPs that are yours, you'd whitelist. Though, I've not had to explicitly whitelist any IPs unless im specifying who can log in to the MGMT console and in some rare cases where STUN devices have somehow got themselves blacklisted.

your 3CX is in Florida and the failed attempt is from the Netherlands, so unless you have someone in the Netherlands, you wont be adding this to your whitelist.

Depending on your set up you may want to consider locking down your ports on your firewall, restricting to your SIP Provider for example.
 
  • Like
Reactions: AWS2P
You ignore the blacklist unless one of your users (or yourself) can't connect. If that happens more than once (or if you want to make sure that never happens) you whitelist. The blacklist/whitelist concept is not new or unique to 3CX.
 
  • Like
Reactions: TBWD
Any IP that is NOT yours or your staff or your SIP Trunk Provider, just leave it on Deny, as soon as it time expires it will remove it from the blacklist. as @kieferschild said, I would advise adding your IP to the Allow, this will prevent you from getting blocked. PBX Hacking is very common and you will get many more attempts.
 
Thank you for the prompt responses and useful information. I understand now.
 
I've not had to explicitly whitelist any IPs

I agree, though we found when first setting up a new SIP trunk provider and guessing at settings it was helpful to whitelist their IPs. Also we whitelist our office IP and usually the client's IP, and only allow those two IPs to log in to the management console. That way someone at the client's office can't accidentally try to log in to the management login page instead of the web client, and lock out the entire office.
 
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,962
Messages
589,993
Members
164,867
Latest member
swegner